Instantiations Logo

SOC 2 at Instantiations: A Milestone and More

May 12, 2026

Josh Wyatt
CISO
News Category: 

Greetings from your friendly Chief Information Security Officer! When I joined Instantiations’ compliance journey three years ago, I was impressed with the extant maturity of operations and controls posture. As the compliance landscape continues to evolve in all the ways and domains of business that embrace technology, we made the decision to pursue SOC 2®. Instantiations Achieved SOC 2 Type 1 in 2024, and recently achieved SOC 2 Type 2 in 2025.

Is it a ticket to the dance? Sure. But while many organizations stop at checking the box, we saw an opportunity not just to leverage it, but to truly embrace and live it.

SOC 2 is not just a credential; it’s an attestation to how we operate, how we manage risk, and how seriously we take the trust our customers place in us.

What SOC 2 Represents

At its core, SOC 2 provides customers and prospects with confidence. It’s a confidence grounded not in claims, but in independent validation.

Our SOC 2 attestation reflects:

  • Verified risk management controls
    Security systems and process design strategy and artifacts like policies are important, as a formal contract with the business itself, but they must be tested and validated to ensure they perform as intended, and create an opportunity for improvement.
  • A commitment to operational maturity
    SOC 2 requires more than documentation. It requires discipline, consistency, and formalized approaches to managing security, compliance, and operational risk.
  • An objective, third-party perspective
    An independent auditor evaluates our controls and processes, providing an unbiased assessment of our overall risk management strategy, beyond isolated technical safeguards.

This transforms SOC 2 from a framework into a signal of trust, but its true value goes beyond compliance.

Beyond a Compliance Checkbox

It’s easy to treat SOC 2 as a one-time effort. A ticket to the dance; a credential to satisfy a customer checklist. However, that purely tactical approach misses the real strategic opportunity.

For Instantiations, SOC 2 is a mechanism to:

  • Continuously evaluate and strengthen our internal processes
  • Align our security and compliance practices with how we actually operate
  • Identify gaps and improve proactively, not reactively

In other words, SOC 2 is not the finish line. It’s part of how we build a more resilient and mature organization over time.

Building on a Strong Foundation

As I mentioned in the intro, we didn’t start from zero.

Instantiations has long prioritized operational excellence, security, and responsible risk management. SOC 2 gives us a structured way to validate and enhance that foundation.

Rather than introducing artificial processes just to meet audit requirements, we’ve focused on:

  • Reinforcing practices that already work
  • Formalizing where structure adds clarity and consistency
  • Ensuring our controls scale with our growth

The result is a program that reflects how we truly operate, not just how we document compliance.

A Partnership with Our Customers

Perhaps most importantly, SOC 2 is really about the organizations we serve.

Our customers operate in an increasingly complex and evolving compliance landscape. Requirements change. Risks shift. Expectations rise.

Our commitment is to be a partner in that environment:

  • Providing transparency into how we manage risk
  • Supporting customer compliance and due diligence efforts
  • Continuously evolving our practices alongside industry standards

Trust is not static, and neither is our approach to earning it.

Looking Ahead

Achieving SOC 2 is an important milestone, but it’s just one step in our broader operational maturity journey, and an opportunity to better support our customers in their own Governance, Risk, and Compliance (GRC) efforts. That’s why Instantiations now offers a structured VAST Compliance Package suite, providing risk management tools that go beyond simply “writing an exception.”

We will continue to invest in our security, compliance, and operational practices to ensure we meet the needs of our customers today, and anticipate the challenges of tomorrow (AI, anyone?). Stay tuned, because there’s more on our roadmap, beyond SOC 2.

Ultimately, this investment and strategy isn’t about passing an audit. It’s about proving, every day, that we are worthy of the trust our customers place in us. In a world teeming with risks, we’re committed to navigating it together.

Together, we can build something great.

GET STARTED
Instantiations Icon
© Instantiations, Inc. All rights reserved. 'Instantiations' and the 'intersecting circle design' are registered trademarks of Instantiations, Inc. in the United States. All product names, trademarks, and registered trademarks are property of their respective owners. Company, product, and service names not owned by Instantiations are used for identification purposes only. Use of these names, trademarks, and brands does not imply endorsement.